When and how AV determines to use heuristics?

Discussion in 'other anti-virus software' started by rpk2006, Mar 6, 2019.

  1. rpk2006

    rpk2006 Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    114
    Location:
    Planet Earth
    I have been thinking on this from a long time. Referred to the documentation and white papers of few products. I found that heuristics is not used by default. Only if there is a suspicion, heuristics is used to verify whether it is a variant.

    How AV identifies that a file is to be checked using heuristics when it is relying on signatures? I guess it applies DNA and cloud labeling only when heuristics flags the file.
     
  2. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    8,251
    Location:
    The land of no identity :D
    Please read fully the paper "malicious code detection technologies" by Alisa shevchenko from Kaspersky labs. The paper is freely available via internet search. Your doubts will be cleared much better. :)
     
  3. rpk2006

    rpk2006 Registered Member

    Joined:
    Jan 29, 2003
    Posts:
    114
    Location:
    Planet Earth
    Thanks.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.